CVE-2026-106441: CWE-94: Improper Control of Generation of Code ('Code Injection') in hydra-ecosystem hydra
Description
CVE-2026-106441 is a high-severity code injection vulnerability in the hydra-ecosystem hydra framework. Versions prior to 1.3.6 and between 1.4.0.dev0 and 1.4.0.dev9 improperly handle Python logging configuration by passing it to logging.config.dictConfig() without enforcing Hydra's target policy on certain logging components. This allows an attacker controlling the logging configuration to invoke arbitrary importable classes or factories with the application's privileges. The issue is fixed in versions 1.3.6 and 1.4.0.dev9.
CVSS v3.1
Score 7.8high
Affected software
hydra-ecosystem
hydra
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Hydra versions before 1.3.6 and from 1.4.0.dev0 up to but not including 1.4.0.dev9 pass Python logging configuration to logging.config.dictConfig() without applying Hydra's target policy to handler class values or formatter, filter, handler, queue, and listener factories. This flaw enables an attacker who can control Hydra logging configuration to select an importable class or factory and cause it to be invoked with the application's privileges, effectively leading to code injection. The vulnerability is addressed in versions 1.3.6 and 1.4.0.dev9.
Potential Impact
An attacker with the ability to control Hydra logging configuration can execute arbitrary code with the application's privileges, potentially leading to full compromise of the affected system. The vulnerability has a CVSS 3.1 score of 7.8, indicating high severity with impacts on confidentiality, integrity, and availability.
Mitigation Recommendations
Upgrade to hydra versions 1.3.6 or later, or 1.4.0.dev9 or later, where this vulnerability is fixed. There are no known mitigations other than applying the official fix. Patch status is confirmed fixed in these versions.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-10-06T16:49:40.590Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac546312cdf04f656d49cbb
Added to database: 10/06/2026, 19:04:17 UTC
Last enriched: 10/06/2026, 23:03:20 UTC
Last updated: 10/06/2026, 23:03:20 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.